VYPR
Medium severity6.5NVD Advisory· Published Aug 18, 2024· Updated Apr 15, 2026

CVE-2024-43307

CVE-2024-43307

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gordon Böhme, Antonio Leutsch Structured Content allows Stored XSS.This issue affects Structured Content: from n/a through 1.6.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS vulnerability in WordPress Structured Content plugin allows authenticated attackers to inject arbitrary scripts.

Vulnerability

Analysis

The Structured Content (JSON-LD WPSC) plugin for WordPress versions through 1.6.2 contains a Stored Cross-Site Scripting (XSS) vulnerability [1]. This issue arises from improper neutralization of user input during web page generation, allowing malicious actors to inject arbitrary HTML and JavaScript code that is stored on the server and executed when other users access the affected page [1].

Exploitation

Prerequisites

Successful exploitation requires an authenticated user with at least contributor-level privileges to inject the malicious payload [1]. While the attack can be initiated by a privileged user, the vulnerability is classified as Stored XSS, meaning the injected script persists and executes automatically for any visitor accessing the compromised content [1]. No direct user interaction is needed for the payload to trigger once stored.

Impact

An attacker can inject arbitrary scripts, redirects, advertisements, or other HTML payloads into the website [1]. This can lead to session hijacking, defacement, or phishing attacks against site visitors. The vulnerability is rated as Medium severity (CVSS 3.1 base score 6.5) [1].

Mitigation

The vulnerability is patched in version 1.6.3 of the plugin [1]. Users are strongly advised to update immediately or enable auto-updates for the plugin. The vendor notes that while the vulnerability is not currently part of mass-exploit campaigns, prompt patching is recommended to prevent potential attacks [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.